Candlepin before 0.7.24, as used in Red Hat Subscription Asset Manager before 1.2.1, does not properly check manifest signatures, which allows local users to modify manifests.
2013-04-02T22:55:01.237
2025-04-11T00:51:21.963
Deferred
CVSSv2: 2.1 (LOW)
AV:L/AC:L/Au:N/C:N/I:P/A:N
3.9
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | candlepinproject | candlepin | ≤ 0.7.2 | Yes |
Application | candlepinproject | candlepin | 0.4.5 | Yes |
Application | candlepinproject | candlepin | 0.4.11 | Yes |
Application | candlepinproject | candlepin | 0.4.27 | Yes |
Application | candlepinproject | candlepin | 0.5.5 | Yes |
Application | candlepinproject | candlepin | 0.6.3 | Yes |
Application | redhat | subscription_asset_manager | ≤ 1.2.0 | Yes |
Application | redhat | subscription_asset_manager | 1.0.0 | Yes |
Application | redhat | subscription_asset_manager | 1.1.0 | Yes |